fix: Sanitized prefix/suffix Htmlable

This commit is contained in:
Dan Harrin
2024-03-07 09:39:06 +00:00
parent d11dd67b0e
commit c6f50266c7
4 changed files with 66 additions and 10 deletions
@@ -259,6 +259,29 @@ TextEntry::make('description')
->html()
```
If you use this method, then the HTML will be sanitized to remove any potentially unsafe content before it is rendered. If you'd like to opt out of this behavior, you can wrap the HTML in an `HtmlString` object by formatting it:
```php
use Filament\Infolists\Components\TextEntry;
use Illuminate\Support\HtmlString;
TextEntry::make('description')
->formatStateUsing(fn (string $state): HtmlString => new HtmlString($state))
```
Or, you can return a `view()` object from the `formatStateUsing()` method, which will also not be sanitized:
```php
use Filament\Infolists\Components\TextEntry;
use Illuminate\Contracts\View\View;
TextEntry::make('description')
->formatStateUsing(fn (string $state): View => view(
'filament.infolists.components.description-entry-content',
['state' => $state],
))
```
### Rendering Markdown as HTML
If your entry value is Markdown, you may render it using `markdown()`:
@@ -9,6 +9,7 @@ use Filament\Support\Contracts\HasLabel as LabelInterface;
use Filament\Support\Enums\ArgumentValue;
use Illuminate\Contracts\Support\Htmlable;
use Illuminate\Support\Carbon;
use Illuminate\Support\HtmlString;
use Illuminate\Support\Number;
use Illuminate\Support\Str;
@@ -228,6 +229,10 @@ trait CanFormatState
'state' => $state,
]);
if ($isHtml) {
$state = Str::sanitizeHtml($state);
}
if ($state instanceof Htmlable) {
$isHtml = true;
$state = $state->toHtml();
@@ -263,6 +268,8 @@ trait CanFormatState
if (filled($prefix)) {
if ($prefix instanceof Htmlable) {
$prefix = $prefix->toHtml();
} elseif ($isHtml) {
$prefix = e($prefix);
}
$state = $prefix . $state;
@@ -271,16 +278,14 @@ trait CanFormatState
if (filled($suffix)) {
if ($suffix instanceof Htmlable) {
$suffix = $suffix->toHtml();
} elseif ($isHtml) {
$suffix = e($suffix);
}
$state = $state . $suffix;
}
if ($isHtml) {
return str($state)->sanitizeHtml()->toHtmlString();
}
return $state;
return $isHtml ? new HtmlString($state) : $state;
}
public function getCharacterLimit(): ?int
@@ -304,6 +304,29 @@ TextColumn::make('description')
->html()
```
If you use this method, then the HTML will be sanitized to remove any potentially unsafe content before it is rendered. If you'd like to opt out of this behavior, you can wrap the HTML in an `HtmlString` object by formatting it:
```php
use Filament\Tables\Columns\TextColumn;
use Illuminate\Support\HtmlString;
TextColumn::make('description')
->formatStateUsing(fn (string $state): HtmlString => new HtmlString($state))
```
Or, you can return a `view()` object from the `formatStateUsing()` method, which will also not be sanitized:
```php
use Filament\Tables\Columns\TextColumn;
use Illuminate\Contracts\View\View;
TextColumn::make('description')
->formatStateUsing(fn (string $state): View => view(
'filament.tables.columns.description-entry-content',
['state' => $state],
))
```
### Rendering Markdown as HTML
If your column contains Markdown, you may render it using `markdown()`:
@@ -9,6 +9,7 @@ use Filament\Tables\Columns\TextColumn;
use Filament\Tables\Table;
use Illuminate\Contracts\Support\Htmlable;
use Illuminate\Support\Carbon;
use Illuminate\Support\HtmlString;
use Illuminate\Support\Number;
use Illuminate\Support\Str;
@@ -228,6 +229,10 @@ trait CanFormatState
'state' => $state,
]);
if ($isHtml) {
$state = Str::sanitizeHtml($state);
}
if ($state instanceof Htmlable) {
$isHtml = true;
$state = $state->toHtml();
@@ -263,6 +268,8 @@ trait CanFormatState
if (filled($prefix)) {
if ($prefix instanceof Htmlable) {
$prefix = $prefix->toHtml();
} elseif ($isHtml) {
$prefix = e($prefix);
}
$state = $prefix . $state;
@@ -271,16 +278,14 @@ trait CanFormatState
if (filled($suffix)) {
if ($suffix instanceof Htmlable) {
$suffix = $suffix->toHtml();
} elseif ($isHtml) {
$suffix = e($suffix);
}
$state = $state . $suffix;
}
if ($isHtml) {
return str($state)->sanitizeHtml()->toHtmlString();
}
return $state;
return $isHtml ? new HtmlString($state) : $state;
}
public function getCharacterLimit(): ?int